Current status
This is a product posture page, not a certification claim. It separates available controls, review artifacts, and roadmap work.Available today
Managed customer application data is hosted in Germany by Hetzner. Duale AI is a French company. The current posture describes tenant isolation, access controls, audit events, scoped retention, and subprocessors for the managed service.
Review artifacts
Security questionnaire answers, architecture notes, data-processing agreement request path, subprocessor list, hosting description, incident contact, and product-control summary can be requested during review. Availability depends on current artifact status and review scope.
Certification status
Duale AI does not currently claim SOC 2, SOC 3, ISO 27001, EU AI Act certification, or equivalent certification. Readiness work is not presented as a completed audit.
No unsupported badges
There is no public SOC 3 PDF, EU AI Act certification, or EU Cloud Code of Conduct adherence claim today. Those labels will appear only after the underlying audit or adherence work is complete.
Document map
The buying review usually needs the same documents. Use this map to ask for the right artifact.Subprocessors
Current subprocessors, roles, processing locations, and transfer safeguards are documented in the legal pages.
Data-processing agreement
The data-processing agreement request path is available during procurement review. The legal pages remain the public source for privacy and processor notices.
ISO 27001 roadmap
ISO 27001 readiness work is not presented as certification.
EU residency map
Managed application data is hosted in Germany today. Website delivery and network protection use Cloudflare edge services.
Model provider card
Customers select and contract with model providers during deployment review. Duale AI treats model routing as configurable infrastructure, not as a hidden bundled provider.
AI Act references
Review inputs can support discussion of logging, transparency, risk management, and human oversight references where those obligations apply. This is not an EU AI Act compliance certification.
Controls that matter for production agents
The platform is designed around stable agent contracts, operational events, and requestable review inputs. Audit exists because production needs it, not as the product category.Track routed work
Submitted work, errors, retries, and routing decisions can be recorded as operational events so teams can understand what happened without reconstructing the workflow from application logs.
Separate tenants and providers
Customer context is scoped by tenant. Model providers are selected in the customer deployment and treated as replaceable infrastructure.
Keep project review explicit
Teams can document risk thresholds, stop paths, and project-specific review requirements around agent work that carries business or security risk.
Limit data movement
Managed application data is hosted in Germany today. Model-provider traffic depends on the providers selected by the customer and the contracts attached to that choice.
Review failures
Timeouts, rejected calls, degraded providers, and failed work can be made visible as product events where the integration captures them, instead of staying hidden inside one-off scripts or notebooks.
Preserve an exit path
Stable input and output contracts make it easier to move models, policies, and deployment targets without rewriting each agent from scratch.
Data processing posture
The legal pages remain the source of truth for contractual privacy and subprocessor details.Managed application data
Managed application data is hosted by Hetzner Online GmbH in Germany. Cloudflare is used for website delivery and network protection.
Model providers
Customers choose and contract directly with model providers. Duale AI does not impose a single model provider as a hidden subprocessor.
Training-use boundary
Training-use commitments are governed by the privacy notice, customer agreements, and selected model-provider contracts. Confirm the exact scope during security review.
Contact paths
Use the channel that matches the review question.Security review
Request a review through the contact form or email contact+security@mail.duale.ai for security-specific questions.
Privacy and data processing
Privacy requests: contact+privacy@mail.duale.ai. Data-processing agreement requests: contact+dpa@mail.duale.ai.
Subprocessor objections
Subprocessor objections and legal notices use contact+legal@mail.duale.ai, as documented in the legal pages.